EX200 Manage security Practice Question
Which THREE commands are used to manage SELinux file security contexts? (Select exactly three.)
⚠ Common exam trap
Red Hat frequently tests the distinction between commands that modify the running SELinux file context (chcon), commands that modify the policy defaults (semanage fcontext), and commands that restore contexts from policy (restorecon). Candidates often confuse 'setenforce' (which controls SELinux enforcing/permissive mode) with context management commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chcon
B (chcon) is correct because it changes the SELinux security context of a file or directory immediately, without reference to the SELinux policy database. This is useful for temporary or one-off changes, but the context may be overwritten by restorecon or a file system relabel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
setenforce
Why it's wrong here
setenforce is a runtime command that toggles the SELinux operating mode between Enforcing and Permissive, or permissive and enforcing, for the current boot session. It does not touch the extended attributes (security.selinux) that store a file's context, so it cannot manage file security labels. Because it alters policy enforcement globally rather than applying a label to an inode, it is not a file-context management tool.
- ✓
chcon
Why this is correct
chcon is the direct, immediate way to change the SELinux context of an existing file or directory by explicitly specifying a context, such as 'chcon -t httpd_sys_content_t /var/www/html/index.html'. It writes the new security.selinux extended attribute value on the file itself, which makes the change take effect right away without a policy reload. However, chcon does not update the persistent SELinux policy mappings, so the label can be lost if restorecon is later run or the filesystem is relabeled.
- ✗
selinux
Why it's wrong here
There is no standard executable or command named 'selinux' in a typical Red Hat Enterprise Linux installation. SELinux administration is performed through utilities such as getenforce, setenforce, sestatus, chcon, restorecon, semanage, and audit2why, among others. Typing 'selinux' at the shell produces a 'command not found' error, so it cannot possibly be used to manage file contexts.
- ✓
semanage fcontext
Why this is correct
semanage fcontext is the persistent, policy-based method for managing SELinux file context mappings in the policy database. It records regular expressions (or path equivalences) that map paths to context types, for example 'semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?"'. These mappings are stored in /etc/selinux/targeted/contexts/files/ and are only applied to actual files when restorecon is run. It does not change the context of a live file; it defines what the default context should be for future relabeling operations.
- ✓
restorecon
Why this is correct
restorecon resets a file or directory's SELinux context to the default stored in the fcontext policy. When executed, it reads the policy mappings and applies the matching context to the file's security.selinux attribute, thereby repairing manually mislabeled or incorrectly chcon'd files. This makes restorecon the standard tool for reverting to the canonical context and is often used after copying or moving files that lack the proper label. It does not create new mappings; it consumes the mappings managed by semanage fcontext.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.